hello all after a long time ....
im working in case with Xiaomi Redmi 4 (4X) model : mag138 and the Chipset : Qualcomm MSM8940 Snapdragon 435 .... the phone is locked via pin and the bootloader is also locked by default ... check result via fastboot :

according to Oleg Afonin from elcomsoft :
Finally, some devices come with locked bootloaders and no service mode or bootloader exploits. These will be the toughest to acquire, as live imaging will probably be your only option when it comes to physical acquisition.

so what to do ?? is there any exploit for this model to bypass the botloader !! and does the chip-off will help in this case ??

There should be a testpoint on the mainboard to force phone to boot into EDL/QDLoader 9008 mode and make physical dump in that mode with some tools but encryption will be a problem. I do believe both Redmi 4 and 4x are encrypted by default.

There should be a testpoint on the mainboard to force phone to boot into EDL/QDLoader 9008 mode and make physical dump in that mode with some tools but encryption will be a problem. I do believe both Redmi 4 and 4x are encrypted by default.

i think there is a several ways(hardware and software ) to enter EDL mode u can read this :

From my experience with newer Xiaomi devices, software methods are already blocked unless you're able to boot the device and use "adb reboot edl". Modified cable (so called edl cable) was blocked in many devices last year. The only working option to enter edl mode is testpoint on mainboard.
I know couple paid hardware (CM2QLM, Volcano, NCK Box etc) or software (Uni-Android etc) methods to make full dump but don't know any free. Best bet would be to look for firmware compatibile with QPST eMMC Download software, load it and use a button called "switch device to DLOAD" which should switch device from 9008 mode to 9006 mode (Qualcomm MMC Storage) that would allow you to make dump with any tool. I'm not sure this will work on those devices since they may not support 9006 mode anymore.

From my experience with newer Xiaomi devices, software methods are already blocked unless you're able to boot the device and use "adb reboot edl". Modified cable (so called edl cable) was blocked in many devices last year. The only working option to enter edl mode is testpoint on mainboard.
I know couple paid hardware (CM2QLM, Volcano, NCK Box etc) or software (Uni-Android etc) methods to make full dump but don't know any free. Best bet would be to look for firmware compatibile with QPST eMMC Download software, load it and use a button called "switch device to DLOAD" which should switch device from 9008 mode to 9006 mode (Qualcomm MMC Storage) that would allow you to make dump with any tool. I'm not sure this will work on those devices since they may not support 9006 mode anymore.

it did not work my friend i cant switch it from 9008 to 9006 mode
this is the testpoint :

\i send an email to salvationdata and they replay :
Thanks for you question!

Our Qualcomm physical extraction in SPF can extract data from Redmi 4(4X), but, if the Android version is based on 6.0 or higher and the data extracted is encrypted.

As we don't provide decryption service, so I suggest you do physical extraction by using our SPF